<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCP Reset being dropped at firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-reset-being-dropped-at-firewall/m-p/422298#M94052</link>
    <description>&lt;P&gt;Please see my article for globalcounters, flow basic and pcap captures for such issues:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-checking-for-drops-rejects-discards/m-p/402102#M91777" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-checking-for-drops-rejects-discards/m-p/402102#M91777&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Jul 2021 11:49:11 GMT</pubDate>
    <dc:creator>NikolayDimitrov</dc:creator>
    <dc:date>2021-07-27T11:49:11Z</dc:date>
    <item>
      <title>TCP Reset being dropped at firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-reset-being-dropped-at-firewall/m-p/421073#M93922</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a client accessing a Citrix CAG via a firewall at one site on HTTP that I see traversing the FW, exist out towards the internal PA firewall reaches its destination.&amp;nbsp; The destination server is sending a TCP RST, we are told to redirect the browser to HTTPS, that TCP reset is sent all the way back to the firewall nearest the client, receive on the interface but the firewall drops it so the client never receives the TCP RST.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In detail....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Client (Internet IP) --- http ---&amp;gt; FW IP&amp;nbsp; [ FW1 VR 1 ] NAT Src 10.1.1.1 Dst NAT 10.2.2.1 --- route to VR 2 ---&amp;gt; [FW 1 VR 2 ] --&amp;gt; Over WAN --&amp;gt;&amp;nbsp; [FW2 VR 1 ] ---&amp;gt; Server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTTP SYN sent and received at Server&lt;/P&gt;&lt;P&gt;Server sends TCP RST&lt;/P&gt;&lt;P&gt;TCP RST reaches FW1 on Rx capture&lt;/P&gt;&lt;P&gt;FW Drop capture logs all TCP RST to client&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone advise why the PA drops TCP RST in such a scenario?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jul 2021 15:41:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-reset-being-dropped-at-firewall/m-p/421073#M93922</guid>
      <dc:creator>GrantCampbell4</dc:creator>
      <dc:date>2021-07-21T15:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Reset being dropped at firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-reset-being-dropped-at-firewall/m-p/422037#M94034</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/185420"&gt;@GrantCampbell4&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Taking packet capture on palo alto will give you more clarity about the flow and what's happening..&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 11:56:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-reset-being-dropped-at-firewall/m-p/422037#M94034</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2021-07-26T11:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: TCP Reset being dropped at firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tcp-reset-being-dropped-at-firewall/m-p/422298#M94052</link>
      <description>&lt;P&gt;Please see my article for globalcounters, flow basic and pcap captures for such issues:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-checking-for-drops-rejects-discards/m-p/402102#M91777" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/knowledge-sharing-palo-alto-checking-for-drops-rejects-discards/m-p/402102#M91777&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jul 2021 11:49:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tcp-reset-being-dropped-at-firewall/m-p/422298#M94052</guid>
      <dc:creator>NikolayDimitrov</dc:creator>
      <dc:date>2021-07-27T11:49:11Z</dc:date>
    </item>
  </channel>
</rss>

